← Back

CVE-2025-0912

nvd nist
Published: Mar 4, 2025Modified: Mar 5, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: security@wordfence.com (Secondary)

Description

The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input from the Donation Form through the 'card_address' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to achieve remote code execution.

Affected (1)

Products: Givewp: Givewp
1 product
Givewp
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.20.0

Timeline

No history available yet.